Nâng cao thành quả an toàn thông tin: Vai trò của hành vi né tránh nguy cơ và sự sẵn sàng của doanh nghiệp
DOI:
https://doi.org/10.24311/jabes/2025.36.7.04Keywords:
Information security performance, Information security readiness, Threat avoidance behavior, VietnamAbstract
Information security (ISe) threats are increasing and seriously impacting sustainable business operations. Due to the lack of studies on ISe performance from a human resource management perspective, this study tested a model to explain how ISe performance is affected by ISe readiness, threat avoidance behavior, and other antecedents. The PLS analysis of 320 enterprises showed that ISe readiness fully mediated the impact of threat avoidance behavior on ISe performance. The authors also confirmed the significant roles of risk avoidance motivation, ISe education, training, awareness programs, and social influence on threat avoidance behavior and ISe readiness. These findings provide business managers, ISe consulting firms, and authorities with insights into strategies to enhance ISe performance.
References
Armstrong, J. S., & Overton, T. S. (1977). Estimating nonresponse bias in mail surveys. Journal of Marketing Research, 14(3), 396-402.
Bandura, A., & Walters, R. H. (1977). Social Learning Theory (Vol. 1). Prentice hall Englewood Cliffs, NJ.
Burns, A., Roberts, T. L., Posey, C., Bennett, R. J., & Courtney, J. F. (2018). Intentions to comply versus intentions to protect: A VIE theory approach to understanding the influence of insiders’ awareness of organizational SETA efforts. Decision Sciences, 49(6), 1187-1228.
Carpenter, D., Young, D. K., Barrett, P., & McLeod, A. J. (2019). Refining technology threat avoidance theory. Communications of the Association for Information Systems, 44.
Chatterjee, S., Sarker, S., & Valacich, J. S. (2015). The behavioral roots of information systems security: Exploring key factors related to unethical IT use. Journal of Management Information Systems, 31(4), 49-87.
Chin, W. W. (1998). The partial least squares approach to structural equation modeling. Modern Methods for Business Research, 295(2), 295-336.
Cisco Systems, I. (2023). Cybersecurity Readiness Index. In: Cisco.
D'Arcy, J., & Devaraj, S. (2012). Employee misuse of information technology resources: Testing a contemporary deterrence model. Decision Sciences, 43(6), 1091-1124.
D'Arcy, J., Hovav, A., & Galletta, D. (2009). User awareness of security countermeasures and its impact on information systems misuse: A deterrence approach. Information Systems Research, 20(1), 79-98.
Davis, F. D., Bagozzi, R. P., & Warshaw, P. R. (1989). User acceptance of computer technology: A comparison of two theoretical models. Management Science, 35(8), 982-1003.
DeLone, W. H., & McLean, E. R. (2003). The DeLone and McLean model of information systems success: A ten-year update. Journal of Management Information Systems, 19(4), 9-30.
Ernest C., S., & Ho, C. B. (2006). Organizational factors to the effectiveness of implementing information security management. Industrial Management & Data Systems, 106(3), 345-361.
Federal Bureau of, I. (2023). Internet Crime Report 2022. Retrieved from https://www.ic3.gov/AnnualReport/Reports/2022_ic3report.pdf?utm_source=chatgpt.com
Fornell, C., & Larcker, D. F. (1981). Structural equation models with unobservable variables and measurement error: Algebra and statistics. Journal of Marketing Research, 18, 382-388.
Hair, J. F., Hult, G. T. M., Ringle, C., & Sarstedt, M. (2017). A Primer on Partial Least Squares Structural Equation Modeling (PLS-SEM) (2 ed.). Sage Publications.
Hair, J. F., Sarstedt, M., Ringle, C. M., & Gudergan, S. P. (2017). Advanced Issues in Partial Least Squares Structural Equation Modeling. Sage Publications.
Hasan, S., Ali, M., Kurnia, S., & Thurasamy, R. (2021). Evaluating the cyber security readiness of organizations and its influence on performance. Journal of Information Security and Applications, 58, 102726.
Henseler, J., Hubona, G., & Ray, P. A. (2016). Using PLS path modeling in new technology research: updated guidelines. Industrial Management & Data Systems, 116(1), 2-20.
Johnston, A. C., & Warkentin, M. (2010). Fear appeals and information security behaviors: An empirical study. MIS Quarterly, 34(3), 549-566.
Khando, K., Gao, S., Islam, S. M., & Salman, A. (2021). Enhancing employees information security awareness in private and public organisations: A systematic literature review. Computers & security, 106, 102267.
Lankton, N. K., Stivason, C., & Gurung, A. (2019). Information protection behaviors: morality and organizational criticality. Information & Computer Security, 27(3), 468-488.
Lebek, B., Uffen, J., Breitner, M. H., Neumann, M., & Hohler, B. (2013). Employees' information security awareness and behavior: A literature review. 2013 46th Hawaii International Conference on System Sciences.
Lee, S. M., Lee, S. G., & Yoo, S. (2004). An integrative model of computer abuse based on social control and general deterrence theories. Information & Management, 41(6), 707-718.
Liang, & Xue. (2009). Avoidance of information technology threats: A theoretical Perspective. MIS Quarterly, 33(1), 71-90.
Lincoln, S. H., & Holmes, E. K. (2011). Ethical decision making: A process influenced by moral intensity. Journal of Healthcare, Science and the Humanities, 1(1), 55-69.
Meltzer, J. P. (2020). Cybersecurity, digital trade, and data flows: Re-thinking a role for international trade rules. https://www.brookings.edu/articles/cybersecurity-digital-trade-and-data-flows-re-thinking-role-for-international-trade-rules/?utm_source=chatgpt.com
Molander, E. A. (1987). A paradigm for design, promulgation and enforcement of ethical codes. Journal of Business Ethics, 6, 619-631.
NCSGroup. (2025). Báo cáo an ninh mạng 2024. Truy cập từ https://ncsgroup.vn/wp-content/uploads/2025/01/NCS-Bao-cao-an-ninh-mang-2024.pdf
Nemati, H. (2007). Information security and ethics: concepts, methodologies, tools, and applications: concepts, methodologies, tools, and applications. IGI global.
Podsakoff, P. M., MacKenzie, S. B., & Podsakoff, N. P. (2012). Sources of method bias in social science research and recommendations on how to control it. Annual Review of Psychology, 63, 539-569.
Puhakainen, P., & Siponen, M. (2010). Improving employees' compliance through information systems security training: An action research study. MIS Quarterly, 34(4), 757-778.
Rashotte, L. (2007). Social Influence. In The Blackwell Encyclopedia of Sociology. https://doi.org/10.1002/9781405165518.wbeoss154
Rezgui, Y., & Marks, A. (2008). Information security awareness in higher education: An exploratory study. Computers & Security, 27(7-8), 241-253.
Rîndașu, S. M. (2017). Emerging information technologies in accounting and related security risks–what is the impact on the Romanian accounting profession. Journal of Accounting and Management Information Systems, 16(4), 581-609.
Rogers, R. W. (1975). A protection motivation theory of fear appeals and attitude change1. The Journal of Psychology, 91(1), 93-114.
Rogers, R. W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In Social psychology: A Sourcebook, (pp.153-176). Guilford
Rosenberg, R. S. (1998). Beyond the code of ethics: The responsibility of professional societies. Proceedings of the Ethics and Social Impact Component on Shaping Policy in the Information Age, https://doi.org/10.1145/276755.276768
Samtani, S., Zhu, H., & Yu, S. (2019). Fear appeals and information security behaviors: An empirical study on Mechanical Turk. AIS Transactions on Replication Research, 5(1), 5.
Siponen, M., & Willison, R. (2009). Information security management standards: Problems and solutions. Information & Management, 46(5), 267-270. https://doi.org/https://doi.org/10.1016/j.im.2008.12.007
Vance, A., & Siponen, M. T. (2012). IS security policy violations: A rational choice perspective. Journal of Organizational and End User Computing (JOEUC), 24(1), 21-41.
Venkatesh, V., Thong, J. Y., & Xu, X. (2012). Consumer acceptance and use of information technology: Extending the unified theory of acceptance and use of technology. MIS Quarterly, 36(1), 157-178.
Vroom, V. (1964). Work and Motivation. Wiley and Sons, New York.
Weiner, B. J. (2020). A theory of organizational readiness for change. In Handbook on Implementation Science (pp. 215-232). Edward Elgar Publishing.
Whitman, & Mattord. (2022). Principles of Information Security (7 ed.). Cengage Learning, Inc.
Young, D. K., Carpenter, D., & McLeod, A. (2016). Malware avoidance motivations and behaviors: A technology threat avoidance replication. AIS Transactions on Replication Research, 2(1), 8.
Downloads
Published
Issue
Section
License
Copyright (c) 2025 JOURNAL OF ASIAN BUSINESS AND ECONOMIC STUDIES

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.



